Modern Web Access Management ‐ Zero Trust Security ‐ from on‐premises to the Cloud
Single Sign On, Access Controls, Session Management and how to use Access Management to protect applications both on premises and in the Cloud
Modern Web Access Management Zero Trust Security from onpremises to - - PowerPoint PPT Presentation
Modern Web Access Management Zero Trust Security from onpremises to the Cloud Single Sign On, Access Controls, Session Management and how to use Access Management to protect applications both on premises and in the Cloud Agenda
Single Sign On, Access Controls, Session Management and how to use Access Management to protect applications both on premises and in the Cloud
2
www.idfconnect.com
3
www.idfconnect.com
4
www.idfconnect.com
5
www.idfconnect.com
SSO‐ Integrated Apps
Access Mgmt Agent / Proxy
SSO‐ Integrated Apps
Access Mgmt Agent / Proxy
SSO‐ Integrated Apps
Access Mgmt Agent / Proxy
Access Manager
Local Users Local Users
Access Management Traffic (vendor‐specific) Active Directory Database, etc. LDAP
Applications in the Traditional Data Center
6
www.idfconnect.com
Server‐side Application Integration AJAX / Mobile / Thick Client Application Integration Applications in the Cloud Access Management as‐a‐Service "Agent‐less" Infrastructure
7
www.idfconnect.com
Authentication Management Access Control Enforcement Single Sign On Risk Scoring & Analytics Session Management Centralized Audit
Web Access Management
8
www.idfconnect.com
Centralized Audit Centralized Audit
Authentication Management Access Control Enforcement Single Sign On Idle Session Timeout Session Maximum Time‐to‐Live
Session Management Risk Scoring & Analytics Access Control Enforcement
Web Access Management (Gaps in the Cloud)
9
www.idfconnect.com
SSO/Rest combines existing and emerging technologies to extend the perimeter of your IAM solution safely and securely into your public Cloud platforms
Rest based‐ lightweight Risk scoring, strong authentication Easy to use, handles latency, transparent…. Modern engineering –
10
www.idfconnect.com
11
www.idfconnect.com
One‐time handoff from partner IDP Limited logout capability Perimeter Defense Audit Access control
www.yourwebsite.com future businessPolicy Enforcement Point (PEP) Policy Decision Point (PDP)
www.yourwebsite.com future businessAuthentication
Session lifecycle management
12
www.idfconnect.com
IIS HTML5
XML Cloud CSS3
Seamless and Secure Integration
Fortune 50 retail company makes an acquisition, and has seamlessly and securely integrated the new web apps with its eCommerce portal, without having to bring the apps in‐house
Successfully Moving .Net applications to Microsoft Azure
Fortune 50 finance company successfully moves its .Net applications to Microsoft Azure while preserving all of its SSO integrations, authentication and access policies, and audit capabilities
js
PHP
Acquired Company Existing Web Apps
.NET
.Net Applications Microsoft Azure
C#
eCommerce Portal
ASP.NET
13
www.idfconnect.com
14
www.idfconnect.com
15
www.idfconnect.com
Data Center
1 Application in the Cloud
IDF Connect SSO/Rest Plugin SSO/Rest Plugin (JSON over HTTPS)
IDF Connect SSO/Rest Gateway
Policy Decision Point External Firewall Internal Firewall Application SSO integration requests to SSO/Rest (optional) Browser AJAX SSO integration requests to SSO/Rest (optional) Browser HTTP(s) requests to application PEP to PDP Traffic
XACML engine
16
www.idfconnect.com
SSO‐ Integrated Apps
IDF Connect SSO/Rest Plugin
SSO‐ Integrated Apps
Policy Enforcement Point
SSO‐ Integrated Apps
Policy Enforcement Point
Policy Decision Point
Local Users Local Users
SSO/Rest Plugin (JSON over HTTPS) Active Directory Database, etc. LDAP IDF Connect SSO/Rest Gateway
Data Center
17
www.idfconnect.com
SSO‐ Integrated Apps
Policy Enforcement Point
SSO‐ Integrated Apps
Policy Enforcement Point
Policy Decision Point
Local Users Local Users
SSO/Rest Plugin (JSON over HTTPS) Active Dir, Database etc. LDAP IDF Connect SSO/Rest Gateway SSO‐ Integrated Apps
IDF Connect SSO/Rest Plugin
Data Center Cloud Platform
18
www.idfconnect.com
SSO‐ Integrated Apps
Policy Enforcement Point
Policy Decision Point
Local Users Local Users
Active Dir, Database etc. LDAP IDF Connect SSO/Rest Gateway
Data Center
SSO‐ Integrated Apps
IDF Connect SSO/Rest Plugin
SSO‐ Integrated Apps
IDF Connect SSO/Rest Plugin XACML Policy Store SSO/Rest XACML queries Policy Evaluation SSO/Rest Plugin (JSON over HTTPS)
19
www.idfconnect.com
SSO‐ Integrated Apps
Policy Enforcement Point
Policy Decision Point
Local Users Local Users
Active Dir, Databases, etc.
LDAP IDF Connect SSO/Rest Gateway
Data Center
SSO‐ Integrated Apps
IDF Connect SSO/Rest Plugin
SSO‐ Integrated Apps
IDF Connect SSO/Rest Plugin XACML Policy Store SSO/Rest XACML queries Policy Evaluation SSO/Rest Plugin (JSON over HTTPS) Authentication Session tokens only!
20
www.idfconnect.com
SSO‐ Integrated Apps
Policy Enforcement Point
Policy Decision Point Local Users Local Users
Active Dir, Database, etc.
LDAP IDF Connect SSO/Rest Gateway
Data Center
SSO‐ Integrated Apps
IDF Connect SSO/Rest Plugin
SSO‐ Integrated Apps
IDF Connect SSO/Rest Plugin XACML Policy Store
SSO/Rest XACML queries
Policy Evaluation
SSO/Rest Plugin (JSON over HTTPS)
Authentication Session tokens only! Cloud Multi‐Factor Authentication Cloud Directory / IDaaS Provider
21
www.idfconnect.com
Policy Decision Point Local Users Local Users
Active Dir, Database, etc.
LDAP IDF Connect SSO/Rest Gateway
Data Center
SSO‐ Integrated Apps
IDF Connect SSO/Rest Plugin
SSO‐ Integrated Apps
IDF Connect SSO/Rest Plugin XACML Policy Store
SSO/Rest XACML queries
Policy Evaluation
SSO/Rest Plugin (JSON over HTTPS)
Authentication Session tokens only! Cloud Multi‐Factor Authentication Cloud Directory / IDaaS Provider
SSO‐ Integrated Apps
IDF Connect SSO/Rest Plugin
22
www.idfconnect.com
IDF Connect SSO/Rest Gateway
Data Center
SSO‐ Integrated Apps
IDF Connect SSO/Rest Plugin
SSO‐ Integrated Apps
IDF Connect SSO/Rest Plugin XACML Policy Store
SSO/Rest XACML queries
Policy Evaluation
SSO/Rest Plugin (JSON over HTTPS)
Authentication Cloud Multi‐ Factor Authentication Cloud Directory / IDaaS Provider
SSO‐ Integrated Apps
IDF Connect SSO/Rest Plugin
23
www.idfconnect.com
Data Center
SSO‐ Integrated Apps
IDF Connect SSO/Rest Plugin
SSO‐ Integrated Apps
IDF Connect SSO/Rest Plugin
SSO/Rest Plugin (JSON over HTTPS)
Cloud Multi‐ Factor Authentication Cloud Directory / IDaaS Provider
SSO‐ Integrated Apps
IDF Connect SSO/Rest Plugin Cloud Access Management Service
24
www.idfconnect.com
Web Servers: App Servers: Web services for all manner of integrations App Platforms: …and other thick clients!
For More Information, Please Visit
IDF Connect, Inc.
2207 Concord Pike #359 Wilmington, DE 19803
Phone: (888) 765‐1611 Fax: (888) 765‐7284 www.idfconnect.com www.linkedin.com/in/rsand @IDFConnect www.facebook.com/IDFConnect @rsand2 Turn SSO/Rest into your Enterprise 2‐ Factor Auth Solution with SSO/MobileKey. For more details visit www.idfconnect.com/products/sso‐ mobilekey/ Also check out our other products: www.idfconnect.com/products